{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w.sys

glindorus

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {26d264d2-014c-4f07-bf2c-ebf9aed40cef}w.sys by glindorus has been detected as adware by 7 anti-malware scanners. It runs as a Windows kernel mode device driver named “{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
StdLib  (signed by glindorus)

Product:
StdLib

Version:
1.4.3.1 built by: WinDDK

MD5:
bb3dbe07f4fefa0f400b6bc3d0b90561

SHA-1:
7f2d8cc29e454d34bc61288b457f174a8da5e49f

SHA-256:
02d9f9ed46256a145c8e3816050e82683633fd2314d423ba715a9f0e862b986c

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 2:37:46 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Cling
2015.0.3398

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14729

Dr.Web
Trojan.BPlug.123
9.0.1.05190

Reason Heuristics
PUP.glindorus.k
14.8.7.21

Vba32 AntiVirus
AdWare.Win64.Yotoon
3.12.26.3

VIPRE Antivirus
Threat.4150696
31208

File size:
51.7 KB (52,920 bytes)

Product version:
1.4.3.1

Copyright:
Copyright © 2013 StdLib

Original file name:
StdLib.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/19/2013 1:00:00 AM

Valid to:
9/20/2015 12:59:59 AM

Subject:
CN=glindorus, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=glindorus, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38CA8426D3AC22743D3790B6CAB486B4

File PE Metadata
Compilation timestamp:
1/31/2014 12:45:28 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:oIsHpnKHCBSqUPJHKQpkJxpKwT2bcWiJmOtX3g2rp3lnHbjiD:vsHRKHLJqQpkYwTsiTtXxt7mD

Entry address:
0xC03E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 62, 50, FF, FF, CC, CC, 74, C1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BC, C4, 00, 00, C0, A0, 00, 00, B4, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 12, C5, 00, 00, 00, A0, 00, 00, EC, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AE, C8, 00, 00, 38, A0, 00, 00, C4, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A6, C9, 00, 00, 10, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EA, C4, 00, 00, FE, C4, 00, 00, D6, C4...
 
[+]

Entropy:
6.3562

Code size:
37 KB (37,888 bytes)

Driver
Display name:
{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove {26d264d2-014c-4f07-bf2c-ebf9aed40cef}w.sys - Powered by Reason Core Security